Commit 96ed75bdbc
96ed75bdbc5df1d6de994046066467422c41e40d
parent: cca4404360
Verified · cmc ci/pages: success ci/test: success
cmc <hello@cleberg.net> · 2026-09-11 01:11 UTC
ci: run jobs in localhost/orgo-ci and publish as orgo-ci
The image is built from .gitbay/Containerfile.ci on the runner host:
rust with clippy, the musl target and openssh-client. pages.sh and
release.sh source .gitbay/bot-ssh.sh, which writes the BOT_SSH_KEY
secret into the workspace and points ssh and git at it with -F; the
instance is GITBAY_SSH rather than the origin URL, which inside the
container is the container itself.
Closes #4
Layout: unified · split
.gitbay/Containerfile.ci
added
+23
| @@ -0,0 +1,23 @@ |
| |
1 | # The image orgo's CI jobs run in. gitbay's runner never pulls, so the |
| |
2 | # operator builds it on the runner host and .gitbay/ci.yml names it by tag. |
| |
3 | # The file is staged in the runner user's home first: a login shell under su |
| |
4 | # cannot read root's stdin, and root's session does not share /tmp with it. |
| |
5 | # |
| |
6 | # scp -P 2222 .gitbay/Containerfile.ci root@gitbay.org:/var/lib/gitbay-runner/orgo-ci.Containerfile |
| |
7 | # ssh -p 2222 root@gitbay.org 'chown ci-runner /var/lib/gitbay-runner/orgo-ci.Containerfile \ |
| |
8 | # && su - ci-runner -s /bin/sh -c "podman build -t localhost/orgo-ci:1 -f orgo-ci.Containerfile ." \ |
| |
9 | # && rm /var/lib/gitbay-runner/orgo-ci.Containerfile' |
| |
10 | # |
| |
11 | # Tagged, not :latest, so a change here is a deliberate bump in ci.yml. |
| |
12 | FROM docker.io/library/rust:1-trixie |
| |
13 | |
| |
14 | # The rust image installs the minimal profile: clippy for the test job, the |
| |
15 | # musl target and its linker for release.sh's second tarball, openssh-client |
| |
16 | # for the pushes. git and ca-certificates are already present. |
| |
17 | RUN rustup component add clippy \ |
| |
18 | && rustup target add x86_64-unknown-linux-musl \ |
| |
19 | && apt-get update \ |
| |
20 | && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ |
| |
21 | musl-tools \ |
| |
22 | openssh-client \ |
| |
23 | && rm -rf /var/lib/apt/lists/* |
.gitbay/bot-ssh.sh
added
+16
| @@ -0,0 +1,16 @@ |
| |
1 | # Sourced by pages.sh and release.sh. The build runs in a container that |
| |
2 | # holds no key of its own; the orgo-ci account's private key (write on this |
| |
3 | # repository) arrives as the BOT_SSH_KEY secret and is written into the |
| |
4 | # workspace beside an ssh config every ssh and git call is pointed at with |
| |
5 | # -F. GITBAY_SSH, set by the runner, is the instance as this build reaches |
| |
6 | # it. Nothing is written outside the workspace. |
| |
7 | : "${BOT_SSH_KEY:?BOT_SSH_KEY secret is not set}" |
| |
8 | : "${GITBAY_SSH:?GITBAY_SSH is not set; the runner is too old}" |
| |
9 | ( |
| |
10 | umask 077 |
| |
11 | printf '%s\n' "$BOT_SSH_KEY" >"$PWD/.bot_key" |
| |
12 | printf 'IdentityFile %s\nIdentitiesOnly yes\nStrictHostKeyChecking accept-new\nUserKnownHostsFile %s\n' \ |
| |
13 | "$PWD/.bot_key" "$PWD/.known_hosts" >"$PWD/.ssh_config" |
| |
14 | ) |
| |
15 | SSH="ssh -F $PWD/.ssh_config" |
| |
16 | export GIT_SSH_COMMAND="$SSH" |
.gitbay/ci.yml
+7
| @@ -2,12 +2,17 @@ |
| 2 | # repository at the pushed commit and runs every step with `sh -c`, stopping at |
2 | # repository at the pushed commit and runs every step with `sh -c`, stopping at |
| 3 | # the first failure. Repository secrets arrive as environment variables. |
3 | # the first failure. Repository secrets arrive as environment variables. |
| 4 | # |
4 | # |
| |
5 | # Jobs run in localhost/orgo-ci, built from .gitbay/Containerfile.ci on the |
| |
6 | # runner host. Publishing goes over SSH as the orgo-ci account; see |
| |
7 | # .gitbay/bot-ssh.sh. |
| |
8 | # |
| 5 | # The runner is Linux, and `runner next` claims the oldest pending build with no |
9 | # The runner is Linux, and `runner next` claims the oldest pending build with no |
| 6 | # platform targeting, so a second runner could not be aimed at macOS jobs. The |
10 | # platform targeting, so a second runner could not be aimed at macOS jobs. The |
| 7 | # darwin tarballs are therefore built on a Mac by .githooks/pre-push at tag time |
11 | # darwin tarballs are therefore built on a Mac by .githooks/pre-push at tag time |
| 8 | # and uploaded to the same release; see RELEASING.org. |
12 | # and uploaded to the same release; see RELEASING.org. |
| 9 | jobs: |
13 | jobs: |
| 10 | test: |
14 | test: |
| |
15 | image: localhost/orgo-ci:1 |
| 11 | steps: |
16 | steps: |
| 12 | - cargo test --locked |
17 | - cargo test --locked |
| 13 | - cargo clippy --all-targets --locked -- -D warnings |
18 | - cargo clippy --all-targets --locked -- -D warnings |
| @@ -17,11 +22,13 @@ jobs: |
| 17 | # Publishes the documentation site by force-pushing the built output to the |
22 | # Publishes the documentation site by force-pushing the built output to the |
| 18 | # `pages` branch, which gitbay serves at https://orgo.krz.sh. A no-op off main. |
23 | # `pages` branch, which gitbay serves at https://orgo.krz.sh. A no-op off main. |
| 19 | pages: |
24 | pages: |
| |
25 | image: localhost/orgo-ci:1 |
| 20 | steps: |
26 | steps: |
| 21 | - sh .gitbay/pages.sh |
27 | - sh .gitbay/pages.sh |
| 22 | |
28 | |
| 23 | # The tag push is the release: binaries, the gitbay release, and crates.io. |
29 | # The tag push is the release: binaries, the gitbay release, and crates.io. |
| 24 | release: |
30 | release: |
| 25 | tags: "v*" |
31 | tags: "v*" |
| |
32 | image: localhost/orgo-ci:1 |
| 26 | steps: |
33 | steps: |
| 27 | - sh .gitbay/release.sh |
34 | - sh .gitbay/release.sh |
.gitbay/pages.sh
+3 −1
| @@ -13,6 +13,8 @@ if [ "${GITBAY_REF:-}" != "main" ]; then |
| 13 | exit 0 |
13 | exit 0 |
| 14 | fi |
14 | fi |
| 15 | |
15 | |
| |
16 | . .gitbay/bot-ssh.sh |
| |
17 | |
| 16 | tmp=$(mktemp -d) |
18 | tmp=$(mktemp -d) |
| 17 | trap 'rm -rf "$tmp"' EXIT |
19 | trap 'rm -rf "$tmp"' EXIT |
| 18 | site="$tmp/site" |
20 | site="$tmp/site" |
| @@ -31,6 +33,6 @@ git -C "$work" -c user.name=gitbay-ci -c user.email=ci@orgo.krz.sh commit -q \ |
| 31 | -m "Publish the documentation site |
33 | -m "Publish the documentation site |
| 32 | |
34 | |
| 33 | Built from ${GITBAY_SHA} by \`orgo build docs -o _site --strict\`." |
35 | Built from ${GITBAY_SHA} by \`orgo build docs -o _site --strict\`." |
| 34 | git -C "$work" push -q --force "$(git remote get-url origin)" HEAD:refs/heads/pages |
36 | git -C "$work" push -q --force "ssh://$GITBAY_SSH/$GITBAY_REPO.git" HEAD:refs/heads/pages |
| 35 | |
37 | |
| 36 | echo "published the site from ${GITBAY_SHA} to the pages branch" |
38 | echo "published the site from ${GITBAY_SHA} to the pages branch" |
.gitbay/release.sh
+3 −5
| @@ -26,9 +26,7 @@ if [ "$tag" != "v$version" ]; then |
| 26 | exit 1 |
26 | exit 1 |
| 27 | fi |
27 | fi |
| 28 | |
28 | |
| 29 | # Reach the forge on whatever host the runner cloned from, rather than a name it |
29 | . .gitbay/bot-ssh.sh |
| 30 | # may not have in known_hosts. |
| |
| 31 | host=$(git remote get-url origin | sed 's#.*://[^@]*@##; s#[:/].*##') |
| |
| 32 | |
30 | |
| 33 | dist=dist |
31 | dist=dist |
| 34 | mkdir -p "$dist" |
32 | mkdir -p "$dist" |
| @@ -52,10 +50,10 @@ done |
| 52 | # Notes come from the annotated tag, so the person cutting the release writes |
50 | # Notes come from the annotated tag, so the person cutting the release writes |
| 53 | # them at the moment they decide to cut it (`git tag -a "$tag" -F notes.md`). |
51 | # them at the moment they decide to cut it (`git tag -a "$tag" -F notes.md`). |
| 54 | git tag -l --format='%(contents)' "$tag" | |
52 | git tag -l --format='%(contents)' "$tag" | |
| 55 | ssh "git@$host" release create "$repo" "$tag" --title "${tag#v}" --file - |
53 | $SSH "$GITBAY_SSH" release create "$repo" "$tag" --title "${tag#v}" --file - |
| 56 | |
54 | |
| 57 | for f in "$dist"/*; do |
55 | for f in "$dist"/*; do |
| 58 | ssh "git@$host" release asset add "$repo" "$tag" "$(basename "$f")" <"$f" |
56 | $SSH "$GITBAY_SSH" release asset add "$repo" "$tag" "$(basename "$f")" <"$f" |
| 59 | echo "attached $(basename "$f")" |
57 | echo "attached $(basename "$f")" |
| 60 | done |
58 | done |
| 61 | |
59 | |